simready-foundation-conform-fet-022-mujoco

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon external data, including validation reports, profile TOML files, and user requests, which could contain instructions to influence the agent's behavior during asset repair.
  • Ingestion points: Untrusted data enters the context via validation reports, profile TOML files, and direct user requests as specified in the Workflow section of SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when processing these external files.
  • Capability inventory: The skill directs the agent to perform file-write operations (modifying USD joint topology and MuJoCo schemas) and to execute validation tools (rerunning profile gates) (SKILL.md).
  • Sanitization: There is no mention of sanitization, filtering, or validation of the external content before it is interpolated into the agent's decision-making process.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:22 PM
Security Audit — agent-trust-hub — simready-foundation-conform-fet-022-mujoco